Zero-Dependency DevSecOps & AI Code Inspection Engine
Fast deterministic SAST analysis combined with contextual OpenRouter AI verification and automated code repairs.
CodeSentry inspects JavaScript, TypeScript, and Python codebases for security vulnerabilities, logic bugs, algorithmic bottlenecks, and resource leaks. Built with a terminal-native dark aesthetic and live typewriter progress telemetry, it offers built-in security detection, interactive code repairs, and dynamic AI-powered security hardening.
Run instantly without cloning or installing dependencies:
# Run directly from GitHub with zero install:
npx github:raelx20/codesentry scan .
# Or install globally from npm:
npm install -g codesentry-ai
codesentry scan .
# Or install directly from GitHub:
npm install -g github:raelx20/codesentryNote: Both
codesentryandcodesentry-aicommand aliases work identically in your shell.
On first run, CodeSentry interactively configures your free OpenRouter API key and saves it to ~/.codesentry/config.json. Subsequent runs never prompt again.
After any scan, CodeSentry provides an interactive improvement menu:
- Whole Codebase Mode: Batch-repairs all detected vulnerabilities and bugs across the entire project.
- Specific Flaw Mode: Two-tier category filter (
Security Flaws,Code Bugs,Efficiency) to select and preview individual issues. - Safe Diff Preview: Color-coded diff card (
- red/+ green) showing the exact file, line, and proposed change. - Confirmation Guard: Requires explicit approval (
Yes, apply fix to file) before writing to disk. - Auto-Verification: Re-initiates scan immediately after fixes are written to confirm the issue is resolved.
Runs out-of-the-box with zero configuration and no external tools or Docker required:
- SQL Injection: Detects template literals, string concatenation, Python f-strings, and
%formatting in queries across JavaScript and Python (db.query,cursor.execute, and query assignments). - Code Injection: Flags dangerous dynamic code execution (
eval(),new Function(), Pythonexec()). - Command Injection: Detects unquoted shell commands and vulnerable
child_process.execinvocations. - Hardcoded Secrets: Identifies hardcoded API tokens, private keys, and credential literals.
- Path Traversal & XSS: Inspects unsanitized file paths in
fs.readFile/res.sendFileanddangerouslySetInnerHTML. - Insecure Cryptography: Flags deprecated hashing algorithms (MD5, SHA-1).
When a codebase is clean (0 vulnerabilities / 0 bugs / perfect):
- 100% AI-Driven: No static hardcoded bullet points. CodeSentry inspects your project context (manifests, frameworks like Express, Fastify, Flask, Django, and structure) and queries the active OpenRouter AI model.
- Architecture-Level Hardening: The AI model provides custom recommendations covering HTTP security headers (Helmet / CSP), rate limiting (DoS mitigation), token flags (HttpOnly/SameSite), and boundary validation.
- One-Click Export: Save the AI suggestions directly to
AI-SECURITY-SUGGESTIONS.mdin your project root.
- Global Config: Stored in
~/.codesentry/config.json(C:\Users\<user>\.codesentry\config.jsonon Windows). codesentry auth: Dedicated dashboard to view masked keys (sk-or-v1-β’β’β’β’β’β’β’β’β’β’β’β’9339), update tokens, or toggle between AI models.codesentry model: Select from top-tier free AI models (poolside/laguna-s-2.1:free,nvidia/nemotron-3-ultra-550b-a55b:free,minimax/minimax-m2.5:free, etc.) with changes persisted globally.
- Continuous Grade: Computes unified security & quality grade (
A+,A,B,C,D,F) and 0β100 score weighted across security, bugs, efficiency, and resource risks. - Historical Trend Tracking: Compares against previous scans (
β² +4% improved,βΌ -2% degraded) persisted locally in~/.codesentry/autograd-history.json. - Self-Learning Offline Memory: Remembers applied fixes locally in
~/.codesentry/autograd-memory.json. When identical or similar patterns reappear, AutoGrad resolves them offline with 0ms latency and zero API calls or quota consumption.
- Deployment Readiness Score: Evaluates readiness percentage (0β100%) and determines deployment gate verdict:
PASSED,WARNING, orBLOCKED. - Container & Docker Checks: Flags root users in containers, unpinned
:latesttags, secrets inENV/ARG, and insecureADDdirectives. - CI/CD Security: Detects unpinned GitHub Actions (requiring commit SHAs), secrets echoed to build logs, and untrusted
pull_request_targetworkflows. - Config & Secrets Guard: Intercepts committed
.envfiles, production debug flags (DEBUG=True), permissive wildcard CORS with credentials, and missing HTTP security headers. - Dedicated Command: Run
codesentry deployguard .or enforce in CI withcodesentry scan . --gate.
- Prompt Injection Defense: Flags direct, un-sanitized user input concatenated into LLM system or chat prompts.
- Model Deserialization Protection: Intercepts insecure weight loading using
pickleor unconstrainedtorch.load(..., weights_only=False)vulnerable to arbitrary code execution. - Agent Sandbox Guards: Flags AI agent tools that execute dynamic shell or eval code directly on model outputs.
- LLM Data Leakage: Prevents transmitting credentials, API keys, or sensitive secrets in model prompt payloads.
- RAG Vector Injection: Scans for un-sanitized query strings interpolated into vector database queries.
- CodeTwin Architectural Modeling: Automatically discovers external HTTP entrypoints, database sinks, shell execution points, and AI prompt interfaces.
- Multi-Step Attack Paths: Correlates static findings to construct end-to-end exploit chains (e.g.
[Route: /api/query] βββΆ [Vulnerability: SQL Injection] βββΆ [Sink: db.query]). - Terminal & Report Visuals: Renders color-coded ANSI attack chain cards in terminal output and interactive Mermaid diagrams in Markdown audit reports.
- Hash-Backed Artifact Identity: Registers datasets, models (ONNX/safetensors/torch), pipeline code and inference records as SHA-256 identities with Merkle-rooted manifests; verification re-hashes everything on disk and reports added/removed/changed files.
- Signed Provenance Chain: Every registration, pipeline identity and inference run appends a canonical-JSON record signed with Ed25519 (per-contributor keys, least-privilege roles), chained by
prev_record_hashand verifiable end-to-end. - One Anchored Verdict:
codesentry vision verifyfuses six dimensions (dataset, model, pipeline, inference, output, provenance) intoVERIFIED/INTEGRITY VIOLATION/INCOMPLETEwith stable exit codes. See "VisionGuard Known Limitations" below and the full design inCodeSentry/docs/visionguard/design.md.
npm install -g codesentry-ai
# Now available globally from any terminal
codesentry scan .
codesentry auth
codesentry modelnpm install --save-dev codesentry
# Run via npx
npx codesentry scan .git clone https://github.com/raelx20/codesentry.git
cd codesentry/CodeSentry
npm install
npm link # or node bin/codesentry.js scan .# Basic scan
codesentry scan .
# Fast static mode (skips cloud AI triage)
codesentry scan . --no-ai
# Pre-deployment readiness analysis & infrastructure gate
codesentry deployguard .
# Enforce strict CI/CD gate (exits with failure if gate is BLOCKED)
codesentry scan . --gate
# Automatic code repair
codesentry scan . --fix
# Configure or check OpenRouter API credentials
codesentry auth
# Interactively toggle AI reasoning models
codesentry model
# VisionGuard: tamper-evident provenance for ML pipelines
codesentry vision init --actor alice # first run in a terminal: generates the keypair
codesentry vision register-data ./dataset --name train --version 1.0.0 --actor alice
codesentry vision register-model model.onnx --id clf
codesentry vision record-pipeline --name htp --version 1.0.0 --code pipeline.py --actor alice
codesentry vision record-inference input.json output.json --model clf --pipeline htp --actor alice
codesentry vision verify --json
# CI / non-TTY: vision init requires --key-file <existing private key>;
# signing commands auto-discover the actor's key (or take --key-file explicitly)
# CLI help & documentation
codesentry --helpCodeSentry uses OpenRouter's free-tier AI models with automated fallback chaining:
| Model ID | Provider | Recommended Use |
|---|---|---|
poolside/laguna-s-2.1:free |
Poolside | Default: Fast, precise syntax & logic analysis |
nvidia/nemotron-3-ultra-550b-a55b:free |
NVIDIA | Complex: Deep polyglot & DevSecOps reasoning |
minimax/minimax-m2.5:free |
MiniMax | High-speed code triage fallback |
nvidia/nemotron-3-super-120b-a12b:free |
NVIDIA | Balanced code review |
mimo/mimo-2.5:free |
Mimo | Fast fallback |
cohere/north-mini-code:free |
Cohere | Specialized code model |
openrouter/auto |
OpenRouter | Ultimate Fallback: Auto-routes to available free model |
Add .codesentryignore to your project root to exclude directories from audits:
node_modules/
dist/
build/
coverage/
*.min.js
*.bundle.js
__pycache__/
.env*
Note: CodeSentry automatically ignores test fixtures (tests/fixtures/) and build caches when scanning user codebases.
Fail pull requests if high-severity vulnerabilities are introduced:
name: CodeSentry Security Gate
on:
push:
branches: [ main, master ]
pull_request:
branches: [ main, master ]
jobs:
security-audit:
name: CodeSentry SAST Inspection
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 20
- name: Run CodeSentry Scan
run: npx github:raelx20/codesentry scan . --severity HIGH
env:
OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }}| Exit Code | Meaning | CI Impact |
|---|---|---|
0 |
Clean scan (0 issues above threshold) | Pass β |
1 |
Violations detected | Fail β |
2 |
Fatal runtime or syntax error | Fail β |
CodeSentry is a pure Node.js CLI tool. It has no native compile steps, requires no Docker daemon, and runs on Windows, macOS, and Linux out-of-the-box.
VisionGuard is tamper-evidence with attribution β not tamper-prevention, and not a proof of quality. Its guarantees stop here:
- A hash proves bit-identity only β never accuracy, safety, fairness or absence of backdoors.
- The local clock is untrusted; timestamps are claims.
- Rollback of the whole store is undetectable without an out-of-band anchor (
--anchor-file/--expected-head). - Output comparison is byte-level; semantically equal JSON fails unless canonical mode was recorded at inference time.
- Execution truth of an inference is only checkable via deterministic re-execution (the demo does this; the general product cannot).
- Key compromise breaks attribution; a malicious contributor can sign valid-but-bad data.
- Tamper-evidence, not tamper-prevention: an attacker with write access can still destroy data.
- No blockchain, no network service and no external transparency log β deliberate.
vision verify exit codes: 0 VERIFIED, 1 integrity violation, 2 usage, 3 incomplete (unchecked/unsigned/unanchored), 4 internal.
Reproducible 9-scenario integrity demonstration (scenarios AβI): node CodeSentry/scripts/visionguard-sih.js β captured output and the manual per-scenario command sequence are in CodeSentry/docs/visionguard/SIH_DEMO.md.
CodeSentry contains a comprehensive test suite (822 tests across 166 suites):
# Run all unit, analyzer, and integration tests
npm test
# Run unit tests only
npm run test:unit
# Run analyzer tests only
npm run test:analyzers